CWE-74
5,001 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
CVEs (5,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" o...Show more |
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a maliciou...Show more |
1Posimyth 1The Plus Addons For Elementor Jun 17, 2026 Jan 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive informa...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditio...Show more |
OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects...Show more |
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset...Show more |
1Safarimontage 1Safari Montage Jun 17, 2026 Dec 30, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting. |
5Apache CiscoDebian+2 more22Cloudcenter Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+19 moreJun 17, 2026 Dec 28, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so...Show more |
1Netgear 10Rbk20 Firmware Rbk40 FirmwareRbk50 Firmware+7 moreJun 17, 2026 Dec 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50...Show more |
1Netgear 10Rbk20 Firmware Rbk40 FirmwareRbk50 Firmware+7 moreJun 17, 2026 Dec 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50...Show more |
1Netgear 10Rbk20 Firmware Rbk40 FirmwareRbk50 Firmware+7 moreJun 17, 2026 Dec 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50...Show more |
1Netgear 32D7800 Firmware Dm200 FirmwareEx2700 Firmware+29 moreJun 17, 2026 Dec 26, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1....Show more |
1Netgear 28Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+25 moreJun 17, 2026 Dec 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R612...Show more |
1Netgear 27Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+24 moreJun 17, 2026 Dec 26, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R612...Show more |
NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection. |
1Engineers Online Portal Project 1Engineers Online Portal Jun 17, 2026 Dec 20, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites a...Show more |
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable. |
An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node. |
1Vault Cli Project 1Vault Cli Jun 17, 2026 Dec 16, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts...Show more |
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. |